detecting-s3-data-exfiltration-attempts

mukul975/detecting-s3-data-exfiltration-attempts · Agent Skill (multi-file)

by mukul975 · bundle

Published · Last updated


Analyze CloudTrail, GuardDuty, Macie, and VPC Flow Logs to detect unauthorized bulk downloads and cross-account data transfers from AWS S3.

SKILL.md

Files

This skill is a package of 4 files. Install with the command above, or download the folder.

  • 📄SKILL.md entry
  • 📁references
  • 📄api-reference.md 2.5 KB
  • 📁scripts
  • ⚙️agent.py 8.0 KB
  • 📄LICENSE 11.0 KB

Related

  1. performing-cloud-native-threat-hunting-with-aws-detective · mukul975 bundle
    Hunt for threats in AWS environments using Detective behavior graphs, entity investigation timelines, GuardDuty finding correlation, and automated entity profiling across IAM users, EC2 instances, and IP addresses.
    24.6k
    repo stars
  2. performing-cloud-log-forensics-with-athena · mukul975 bundle
    Query AWS CloudTrail, VPC Flow Logs, S3 access logs, and ALB logs with Athena for forensic investigation of security incidents.
    24.6k
    repo stars
  3. performing-cloud-forensics-with-aws-cloudtrail · mukul975 bundle
    Investigate AWS account compromises by querying CloudTrail logs to reconstruct attacker activity, identify compromised credentials, and analyze API call patterns.
    24.6k
    repo stars
  4. detecting-cryptomining-in-cloud · mukul975 bundle
    Detect and respond to unauthorized cryptocurrency mining in AWS and Azure environments using cost anomalies, compute utilization, network traffic analysis, and runtime monitoring.
    24.6k
    repo stars
  5. implementing-security-chaos-engineering · mukul975 bundle
    Deliberately disables or degrades security controls to verify detection and response capabilities, including WAF bypass, firewall rule removal, log pipeline disruption, and EDR disablement scenarios using boto3 and subprocess.
    24.6k
    repo stars
  6. performing-aws-account-enumeration-with-scout-suite · mukul975 bundle
    Enumerate AWS resources and identify misconfigurations using ScoutSuite to generate interactive security reports.
    24.6k
    repo stars

Frequently asked questions

How do I install the detecting-s3-data-exfiltration-attempts skill?

Run npx skillmds add mukul975/detecting-s3-data-exfiltration-attempts in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the detecting-s3-data-exfiltration-attempts skill do?

Analyze CloudTrail, GuardDuty, Macie, and VPC Flow Logs to detect unauthorized bulk downloads and cross-account data transfers from AWS S3. It is listed under Security, DevOps & Infra, Incident Response, Vulnerability Scanning on SkillMD.

Is detecting-s3-data-exfiltration-attempts safe to use?

SkillMD's automated safety review verdict for this skill is CAUTION. Independent scanners report: SkillSpector: PASS, Skill Scanner: PASS. Capability flags: executes scripts, reads secrets. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with detecting-s3-data-exfiltration-attempts?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is detecting-s3-data-exfiltration-attempts free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published detecting-s3-data-exfiltration-attempts?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.